GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,425
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
420 advisories
Filter by severity
Jenkins mabl Plugin missing permission check
Moderate
CVE-2023-37953
was published
for
com.mabl.integration.jenkins:mabl-integration
(Maven)
Jul 12, 2023
Jenkins Datadog Plugin does not perform a permission check in an HTTP endpoint.
Moderate
CVE-2023-37944
was published
for
org.datadog.jenkins.plugins:datadog
(Maven)
Jul 12, 2023
Jenkins SAML Single Sign On(SSO) Plugin missing permission check
Moderate
CVE-2023-37945
was published
for
io.jenkins.plugins:miniorange-saml-sp
(Maven)
Jul 12, 2023
Jenkins Test Results Aggregator Plugin missing permission check
Moderate
CVE-2023-37956
was published
for
org.jenkins-ci.plugins:test-results-aggregator
(Maven)
Jul 12, 2023
Sealos billing system permission control defect
High
CVE-2023-36815
was published
for
github.com/labring/sealos
(Go)
Jun 30, 2023
Jenkins Team Concert Plugin does not perform permission checks in methods implementing form validation
Moderate
CVE-2023-3315
was published
for
org.jenkins-ci.plugins:teamconcert
(Maven)
Jun 19, 2023
Mattermost Server Missing Authorization vulnerability
Moderate
CVE-2023-2783
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Jun 16, 2023
Jenkins Digital.ai App Management Publisher Plugin missing permission checks
Moderate
CVE-2023-35149
was published
for
org.jenkins-ci.plugins:ease-plugin
(Maven)
Jun 14, 2023
OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning
Moderate
CVE-2023-34234
was published
for
@openzeppelin/contracts
(npm)
Jun 8, 2023
Duplicate Advisory: Grafana Improper Access Control vulnerability
Moderate
GHSA-wm7r-3qxj-5xgq
was published
for
github.com/grafana/grafana
(Go)
Jun 6, 2023
•
withdrawn
Missing authorization in Liferay portal
High
CVE-2023-33948
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Synapse does not apply enough checks to servers requesting auth events of events in a room
High
CVE-2022-39335
was published
for
matrix-synapse
(pip)
May 24, 2023
Command injection in nevado-jms
High
CVE-2023-31826
was published
for
org.skyscreamer:nevado-jms
(Maven)
May 23, 2023
Answer Missing Authorization vulnerability
Low
CVE-2023-2590
was published
for
github.com/answerdev/answer
(Go)
May 9, 2023
Missing permission check of canView in GridFieldPrintButton
Moderate
CVE-2023-22728
was published
for
silverstripe/framework
(Composer)
Apr 26, 2023
matrix-js-sdk vulnerable to invisible eavesdropping in group calls
Moderate
CVE-2023-29529
was published
for
matrix-js-sdk
(npm)
Apr 14, 2023
Jenkins Thycotic Secret Server Plugin missing permissions check
Moderate
CVE-2023-30518
was published
for
io.jenkins.plugins:thycotic-secret-server
(Maven)
Apr 12, 2023
Jenkins Quay.io trigger Plugin webhook endpoint can be accessed without authentication
Moderate
CVE-2023-30519
was published
for
org.jenkins-ci.plugins:quayio-trigger
(Maven)
Apr 12, 2023
Jenkins Report Portal Plugin missing permissions check
Moderate
CVE-2023-30526
was published
for
org.jenkins-ci.plugins:reportportal
(Maven)
Apr 12, 2023
Jenkins Fogbugz Plugin has missing permissions check
Moderate
CVE-2023-30522
was published
for
org.jenkins-ci.plugins:fogbugz
(Maven)
Apr 12, 2023
Jenkins Assembla merge request builder Plugin missing authentication to access endpoint
Moderate
CVE-2023-30521
was published
for
org.jenkins-ci.plugins:assembla-merge-request-builder
(Maven)
Apr 12, 2023
Lack of authentication mechanism in Jenkins TurboScript Plugin webhook
Moderate
CVE-2023-30532
was published
for
org.jenkinsci.plugins.spoonscript:spoonscript
(Maven)
Apr 12, 2023
HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation
High
CVE-2023-1782
was published
for
github.com/hashicorp/nomad
(Go)
Apr 5, 2023
Apache James server's JMX management service vulnerable to privilege escalation by local user
High
CVE-2023-26269
was published
for
org.apache.james:javax-mail-extension
(Maven)
Apr 3, 2023
Jenkins OctoPerf Load Testing Plugin missing permission check allows for unauthorized server connections
Moderate
CVE-2023-28675
was published
for
org.jenkinsci.plugins:octoperf
(Maven)
Apr 2, 2023
ProTip!
Advisories are also available from the
GraphQL API